QuestStack — Updated!
Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.
Read more...
Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.
Read more...
CVE-2026-8347 — Updated!
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
Read more...
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
Read more...
CICD-Goat-Vapt-Writeup — Updated!
Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.
Read more...
Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.
Read more...
kcmd — Updated!
Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt commands/responses. This is a PoC project to demonstrate hijacking the socket and sniffing of kankun passwords. This will work on an Android device.
Read more...
Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt commands/responses. This is a PoC project to demonstrate hijacking the socket and sniffing of kankun passwords. This will work on an Android device.
Read more...
CVE-2026-16723 — Updated!
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
Read more...
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
Read more...
Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation — Updated!
Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check Point Security Gateway. Includes comprehensive SIEM analysis, firewall logs, raw web access log inspection (`/var/log/access.log`), IOCs, MITRE ATT&CK mapping, and post-exploitation validation.
Read more...
Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check Point Security Gateway. Includes comprehensive SIEM analysis, firewall logs, raw web access log inspection (`/var/log/access.log`), IOCs, MITRE ATT&CK mapping, and post-exploitation validation.
Read more...
How I Discovered One of My Most Creative Bugs in Google’s Gemini AI Competition
Sometimes, a vulnerability starts with nothing more than a simple question: “Why is this happening?”Continue reading on Medium »
Read more...
Sometimes, a vulnerability starts with nothing more than a simple question: “Why is this happening?”Continue reading on Medium »
Read more...
Medium
How I Discovered One of My Most Creative Bugs in Google’s Gemini AI Competition
Sometimes, a vulnerability starts with nothing more than a simple question: “Why is this happening?”
ghostlock — Updated!
Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free
Read more...
Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free
Read more...
CVE-2026-59941 — Updated!
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Read more...
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
Read more...
ida\_kcpp — Updated!
An IDAPython module for enhancing c++ support on top of ida_kernelcache
Read more...
An IDAPython module for enhancing c++ support on top of ida_kernelcache
Read more...
YellowKey-Bitlocker-CVE-2026-45585 — Updated!
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.
Read more...
Manage BitLocker recovery keys, unlock encrypted drives, and monitor encryption status with this lightweight Windows utility.
Read more...
CVE-2026-18718 — Updated!
Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector
Read more...
Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector
Read more...
UltimateWDACBypassList — Updated!
A centralized resource for previously documented WDAC bypass techniques
Read more...
A centralized resource for previously documented WDAC bypass techniques
Read more...
BAS-Guardian — Updated!
Free BACnet/BMS vulnerability scanner for building automation systems. Detects CVE-2026-3611 (CVSS 10.0), CVE-2026-24060, and exposed HVAC/BAS controllers via PowerShell or Bash.
Read more...
Free BACnet/BMS vulnerability scanner for building automation systems. Detects CVE-2026-3611 (CVSS 10.0), CVE-2026-24060, and exposed HVAC/BAS controllers via PowerShell or Bash.
Read more...
pac4j-check v0.2.0
Offline scanner for CVE-2026-29000 (CVSS 10.0) in org.pac4j:pac4j-jwt. Inspects jars/fat-jars directly, so it works where mvn dependency:tree cannot. Single jar, zero dependencies, Java 8+.
Read more...
Offline scanner for CVE-2026-29000 (CVSS 10.0) in org.pac4j:pac4j-jwt. Inspects jars/fat-jars directly, so it works where mvn dependency:tree cannot. Single jar, zero dependencies, Java 8+.
Read more...
CVE-2025-3052 — Updated!
Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.
Read more...
Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.
Read more...
CVE-2025-4275 — Updated!
Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce attacker-controlled certificates trusted by subsequent boot components.
Read more...
Analysis and exploitation of CVE-2025-4275 (Hydr0ph0bia), a Secure Boot trust-chain weakness where firmware variables are used to introduce attacker-controlled certificates trusted by subsequent boot components.
Read more...
CVE-2026-25250 — Updated!
Analysis and exploit for CVE-2026-25250, a Secure Boot bypass in Horizon DataSys Reboot Restore where shdloader.efi loads Shield.efi without verification.
Read more...
Analysis and exploit for CVE-2026-25250, a Secure Boot bypass in Horizon DataSys Reboot Restore where shdloader.efi loads Shield.efi without verification.
Read more...